July 2026 Release Notes
The Command Platform release notes include information about what’s new, which are updated monthly, and improvements and fixes, which are updated weekly.
Last updated: July 13, 2026
What’s New
Learn about new features across the Command Platform. These features were released over the past month and are available now:
- Risk: Attack Surface Management (Surface Command), Exposure Command
- Focus remediation efforts with CVE publish date filtering
- Surface Microsoft Defender recommendations in Remediation Hub
- Generate and schedule Top Remediation reports from Remediation Hub
- Access Remediation Hub with Vulnerability Management (InsightVM) role-based permissions
- Monitor remediation workflow activity in Remediation Hub
- Threat: Digital Risk Protection (Threat Command)
Risk
Risk is the potential for loss or damage to your assets, operations, or reputation, due to vulnerabilities being exploited by a bad actor. Security teams must assess the risk level by evaluating the likelihood of a threat occurring and the impact that it would have if realized.
- Focus remediation efforts with CVE publish date filtering
- Surface Microsoft Defender recommendations in Remediation Hub
- Generate and schedule Top Remediation reports from Remediation Hub
- Access Remediation Hub with Vulnerability Management (InsightVM) role-based permissions
- Monitor remediation workflow activity in Remediation Hub
Focus remediation efforts with CVE publish date filtering
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes a CVE Publish Date filter, allowing you to view and filter remediations based on when vulnerabilities were publicly disclosed. This helps you identify newly disclosed threats or long-standing vulnerabilities to prioritize remediation efforts effectively.
With this capability from Risk > Remediation Hub, you can:
- Prioritize newly disclosed vulnerabilities using CVE publish date filters.
- Support SLA-driven prioritization and backlog management.
- Target remediation efforts more effectively based on threat timeline.
- Align remediation workflows with organizational priorities and deadlines.
Surface Microsoft Defender recommendations in Remediation Hub
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes Microsoft Defender as a third-party remediation source. Customers using the latest Microsoft Defender connector for Attack Surface Management (Surface Command) can view Defender recommendations alongside remediation data from other sources, reducing context switching and helping your team prioritize the highest-impact fixes.
With this capability from Risk > Remediation Hub, you can:
- View Microsoft Defender remediation recommendations directly in Remediation Hub.
- Prioritize Defender findings alongside data from other remediation sources.
- Manage remediation activity in a centralized workflow to reduce context switching.
Generate and schedule Top Remediation reports from Remediation Hub
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes reporting capabilities based on the Vulnerability Management (InsightVM) Top Remediations report. Generate high-level summary and detailed asset-level reports to prioritize actions, understand impacted assets, and share remediation insights across teams. Reports are available on-demand or on a schedule, in PDF, HTML, and CSV formats.
With this capability from Risk > Remediation Hub, you can:
- Generate summary and asset-level reports on-demand or on a schedule.
- Share reports in PDF, HTML, and CSV formats with security and IT teams.
- Automatically deliver scheduled reports to asset owners to reduce manual follow-up.
- Prioritize remediation across a hybrid environment with data from Vulnerability Management (InsightVM), Cloud Security (InsightCloudSec), and Attack Surface Management.
Access Remediation Hub with Vulnerability Management (InsightVM) role-based permissions
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub is now available to all Vulnerability Management (InsightVM) users — no administrator privileges required. Role-based permissions ensure each user sees only the assets and remediations they are authorized to access, so asset owners can act on prioritized remediations for their assigned assets without relying on security team intervention.
With this capability from Risk > Remediation Hub, you can:
- Access Remediation Hub as any Vulnerability Management (InsightVM) user.
- View only the assets and remediations within your authorized scope.
- See filters and metrics that automatically reflect your assigned asset data.
Monitor remediation workflow activity in Remediation Hub
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now surfaces workflow activity directly, giving security teams visibility into which workflows have run, execution counts, status, and related artifacts such as Jira tickets and ServiceNow incidents — without leaving the remediation workflow.
With this capability from Risk > Remediation Hub, you can:
- View workflow execution history directly in Remediation Hub.
- Monitor execution status, including successful, failed, and in-progress runs.
- Access generated artifacts and workflow outputs in a centralized location.
Threat
A threat is any potential event or action that could exploit vulnerabilities in a system, causing harm to assets, data, or operations. Threats can originate from various sources, including malicious actors, natural disasters, or unintentional human errors.
Control infostealer alert scope with the external user toggle
In Digital Risk Protection (Threat Command), you can now control whether infostealer alerts include external user matches — credentials associated with a customer-owned domain but without an organizational email address. This gives security teams more control over alert volume without sacrificing visibility into employee credential exposure.
With this capability from Intelligence > DRP Configurations > Customization (or Configurations > Customization in Digital Risk Protection (Threat Command)), you can:
- Toggle external user alerting on or off to refine infostealer alert scope.
- Reduce alert noise by disabling monitoring of external email matches while continuing to monitor internal organizational emails.
- Apply the setting to future alerts only, with no impact on existing or previously resolved alerts.
Updated admin group identification for cloud identity providers
In SIEM (InsightIDR), how cloud admin users are identified has been updated. Admin users from cloud identity providers such as Okta and Entra ID are now determined by membership in a group with a recognized admin role applied, rather than by group name alone. This change improves the accuracy of admin user identification across cloud environments.
Improved AI-powered query generation
We’ve enhanced AI-powered Log Search query generation to better understand natural language prompts and reduce the manual effort required to build searches.
It can now:
- Automatically interpret natural language time expressions, such as “yesterday” or “last 24 hours”, and apply the appropriate time range to the search.
- Suggest relevant log sources and event source types based on the intent of your prompt.
- Provide a more detailed AI Query Explanation that includes the selected time range and log sources, making it easier to understand how your prompt was translated into a search query.
These improvements help you create more accurate searches faster while providing greater transparency into how AI interprets your requests.
Improvements and Fixes
Keep track of improvements and fixes to core technology.
Application Security (InsightAppSec) and AppSpider
No updates released at this time.
Attack Surface Management (Surface Command)
Version 1.0.928
Software release date: July 8, 2026 | Release notes published: July 13, 2026
Improved:
- Connector update failures now include an Update Now button to facilitate immediate resolution.
- The Connectors page now supports reviewing and applying multiple connector updates simultaneously.
- Correlation Rules now display human-readable names and descriptions for automatic exclusion rules to improve clarity and usability.
Fixed:
- Hostname and Domain filters now return matching records consistently across Network Services and Certificates pages.
- The Test Connection button in Connector profile now displays a tooltip and disables when the test function is unavailable, preventing runtime errors.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
New Connectors
- Nutanix Prism Central: Nutanix Prism Central is a centralized multi-cluster management plane that provides a single pane of glass for managing Nutanix infrastructure including virtual machines, hosts, clusters, networks, and images. This connector integrates with the Nutanix Prism Central v4 APIs to import infrastructure asset data into the Rapid7 Platform.
Updated Connectors
- IGEL UMS: Fixed a schema validation error for the IgelUmsDevice type.
- Microsoft Entra ID (formerly Azure AD): Added the
AzureAdAppRoleAssignmenttype; app role assignments are now fetched as part of the applications feed. - SentinelOne Singularity: Added the new
SentinelOneSoftwareInstallationtype, linking per-agent installed software toSentinelOneSoftware.
Version 1.0.926
Software release date: July 2, 2026 | Release notes published: July 6, 2026
Improved:
- Executed queries now display 25 results instead of 10 for better readability.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
Updated Connectors
- BigFix: Fixed a packaging error.
- EZO AssetSonar:
- Fixed schema type mismatches in
EzoAssetSonarMember. - Added previously undeclared API fields to
EzoAssetSonarAsset. - Pinned dependencies.
- Fixed schema type mismatches in
- IGEL UMS: Fixed a schema validation error for
IgelUmsDevice. - Kaseya VSA 10: Added Applied Policies enrichment with the M1051 (Update Software) mitigation.
- Kaseya VSA 9: Added the M1051 (Update Software) mitigation to
KaseyaVSA9Agentusing the patch scan status API. - ManageEngine ServiceDesk Plus: Added schema validation for the
ManageEngineServiceDeskUsertype. - Matrix42 CMDB: Added Asset filter to only import assets with an operational status of Active.
- Nozomi Vantage:
- Added Nozomi certification headers (
nn-appandnn-app-version) to all requests. - Added retry handling for API throttling responses (HTTP 429 and HTTP 503).
- Improved vulnerability pagination and deduplication handling.
- Added Nozomi certification headers (
- SolarWinds IT Asset Management: Fixed hostname correlation.
Cloud Security (InsightCloudSec)
Release availability for self-hosted users
Self-hosted users are able to download the latest version usually 4 business days after SaaS users are upgraded from the following locations:
- Terraform deployments: Public S3 bucket . Modules can be updated with the
terraform get -updatecommand. - Amazon Elastic Container Repository (ECR) deployments: You can obtain the ECR build images for this version from the InsightCloudSec ECR Gallery
Version 26.7.7
Software release date: July 9, 2026 | Release notes published: July 9, 2026
Improved
- Added background job
OrphanedCredentialCleanupthat removes orphaned cloud credentials daily or on-demand. These orphaned credentials are unused by harvesting or other portions of the product.
New Insights
- Ensure EC2 Auto Scaling Groups Propagate Tags to Launched Instances (Insight ID 2582) - Detects AWS Auto Scaling Groups where one or more tags are not configured to propagate to the EC2 instances they launch. This aligns with CIS AWS Compute Services Benchmark control 2.14.
- Supported Clouds: AWS, AWS China, AWS GovCloud.
- Compliance Pack Mappings: CIS Controls v8.1.2 (1.1), NIST 800-53 Rev 5 (CM-8, CM-8(1), PM-5), NIST 800-171 (3.4.1, 3.4.9, 3.12.4), NIST CSF 2.0 (ID.AM-01, ID.AM-07), CMMC Level 2 (CM.L2-3.4.1, CA.L2-3.12.4).
- After re-harvesting, Auto Scaling Groups will show tag propagation compliance status. Groups with no tags are considered compliant. Groups not yet re-harvested will show as “unknown” and will not trigger findings.
- Volume Not Marked for Deletion on Instance Termination (Insight ID 2591) - Identifies EBS Volumes attached to EC2 Instances that are not configured for automatic deletion upon Instance Termination, helping reduce orphaned resources and potential data exposure. Aligned with CIS AWS Compute Services Benchmark Control 2.12.
- Compliance Pack Mappings: CIS Controls v8.1.2, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, NIST CSF v2.0, and CMMC Level 2.
- Instance Using Default Security Group - Identifies AWS EC2 Instances that are associated with a default security group rather than a specified custom security group.
- Cloud Account Organization Without Tag Policy Enabled - Identifies management Cloud Accounts whose AWS Organization does not have Tag Policies enabled.
New Query Filters
- Autoscaling Group Not Propagating Tags at Launch - Identifies Auto Scaling Groups where tags are not configured to propagate to launched instances.
- Supported Clouds: AWS, AWS China, AWS GovCloud.
- Cloud Account Organization Tag Policy Status - Identifies management Cloud Accounts based on Tag Policy enablement status at the Organization root.
New Compliance Pack
- Added CIS Red Hat OpenShift Container Platform Benchmark v1.9.0 compliance pack.
Fixed
- Fixed Cache Instance Auth Token Disabled Query Filter false positive. The filter now correctly inherits
auth_tokenconfiguration. - Fixed Resource Associated With Public Subnet Query Filter to correctly detect ElastiCache public subnet associations in CloudFormation Template (CFT) scans.
- Fixed an error that could cause IaC scan listing to fail with a database session error.
- Fixed an issue where resources with exceptions were not showing on the misconfiguration UI and export.
- Resolved intermittent Azure snapshot harvesting failures. Fixed an issue where the Azure snapshot harvester could intermittently fail with a
NotImplementedError, preventing snapshot data from being collected during affected harvest runs.- The snapshot harvesting method is now defined directly on the Azure backend class, consistent with how all other cloud providers (AWS, GCP, AliCloud, Oracle) are implemented.
- No changes to harvested data or behavior — runs that previously succeeded continue to work identically.
Mimics Infrastructure as Code (IaC) Scanning Tool
No updates released at this time.
SIEM (InsightIDR)
No updates released at this time.
Vulnerability Management (InsightVM)
Version 8.52.0
Software release date: July 13, 2026 | Release notes published: July 13, 2026
Improved:
- Improved Splunk Enterprise fingerprinting on Unix/Linux. Added a dedicated fingerprinter that detects Splunk Enterprise by querying the product directly for its version, replacing the previous OS package-based detection.This improves coverage for Splunk installations deployed outside the system package manager (e.g., tarball installs under /opt/splunk), resulting in more accurate software inventory and vulnerability assessment on affected hosts.
- Added fingerprinting support for AI tools, MCP servers, and AI development skills, providing greater visibility into AI technologies deployed across your environment to help identify both authorized and unauthorized usage.
- Added fingerprinting support for Microsoft Intune-managed applications. The scan engine can now detect and inventory software deployed and managed through Microsoft Intune (Microsoft Endpoint Manager), including Win32 apps, MSI line-of-business apps, and Microsoft Store for Business apps. This enhancement enables accurate software fingerprinting on Windows 10/11 endpoints enrolled in Intune, with proper version reporting that matches the Intune console. Duplicate software entries are reconciled when both a local installer and an Intune-managed installer are detected for the same application. Vulnerability assessments are automatically applied to discovered Intune-managed software where existing content coverage is available.
Fixed:
- Resolved an issue where the scan engine incorrectly reported a Diffie-Hellman key size of 0 for TLS 1.3 services.
- Fixed an issue where wildcard CVE searches in the General Search vulnerability tab could return incomplete or incorrect results. Wildcard prefix matching now behaves as expected.
- Addressed an issue preventing reverse-paired Scan Engines from reconnecting automatically after a Security Console restart. Previously paired engines now reconnect as expected.
- Fixed an issue that could cause PostgreSQL 15 major version migrations to fail during upgrade. Database migrations now complete successfully.
Version 8.51.0
Software release date: July 7, 2026 | Release notes published: July 6, 2026
Improved:
- Enhanced Oracle Access Management fingerprinting to improve patch version identification and reporting accuracy.
- Improved scan logging for custom service names configuration issues, providing clearer messages when files are missing or cannot be parsed to simplify troubleshooting.
- Strengthened the overall security posture of the Security Console by upgrading the bundled Axios library to the latest supported minor version.
- Improved the performance and responsiveness of the Asset Search API, particularly for larger Security Console deployments.
- Added built-in policy support for:
- DISA STIG Microsoft SQL Server Database 2022 Benchmark V1R3
- DISA STIG Microsoft SQL Server Instance 2022 Benchmark V1R4
- Operating System Support: Added support for Microsoft Windows Server 2025 on the Vulnerability Management (InsightVM) Console, Nexpose Console, and Scan Engines.
Fixed:
- Resolved an issue where the GET Scan Engine Sites API returned an incomplete value for scanTemplateName. The endpoint now returns the expected scan template name.
- Fixed an issue where CSV vulnerability reports did not include tabular solution content, such as Windows Registry settings and configuration values. This information is now exported correctly.
- Resolved an issue affecting Extensible Ingress when using a console proxy. Exposure Analytics traffic now correctly routes through the configured proxy, including authenticated proxies. A Security Console restart is required when using an authenticated proxy.
Nexpose
Nexpose Version 8.52.0
Software release date: July 13, 2026 | Release notes published: July 13, 2026
Improved:
- Improved Splunk Enterprise fingerprinting on Unix/Linux. Added a dedicated fingerprinter that detects Splunk Enterprise by querying the product directly for its version, replacing the previous OS package-based detection.This improves coverage for Splunk installations deployed outside the system package manager (e.g., tarball installs under /opt/splunk), resulting in more accurate software inventory and vulnerability assessment on affected hosts.
- Added fingerprinting support for AI tools, MCP servers, and AI development skills, providing greater visibility into AI technologies deployed across your environment to help identify both authorized and unauthorized usage.
- Added fingerprinting support for Microsoft Intune-managed applications. The scan engine can now detect and inventory software deployed and managed through Microsoft Intune (Microsoft Endpoint Manager), including Win32 apps, MSI line-of-business apps, and Microsoft Store for Business apps. This enhancement enables accurate software fingerprinting on Windows 10/11 endpoints enrolled in Intune, with proper version reporting that matches the Intune console. Duplicate software entries are reconciled when both a local installer and an Intune-managed installer are detected for the same application. Vulnerability assessments are automatically applied to discovered Intune-managed software where existing content coverage is available.
Fixed:
- Resolved an issue where the scan engine incorrectly reported a Diffie-Hellman key size of 0 for TLS 1.3 services.
- Fixed an issue where wildcard CVE searches in the General Search vulnerability tab could return incomplete or incorrect results. Wildcard prefix matching now behaves as expected.
- Addressed an issue preventing reverse-paired Scan Engines from reconnecting automatically after a Security Console restart. Previously paired engines now reconnect as expected.
- Fixed an issue that could cause PostgreSQL 15 major version migrations to fail during upgrade. Database migrations now complete successfully.
Nexpose Version 8.51.0
Software release date: July 7, 2026 | Release notes published: July 6, 2026
Improved:
- Enhanced Oracle Access Management fingerprinting to improve patch version identification and reporting accuracy.
- Improved scan logging for custom service names configuration issues, providing clearer messages when files are missing or cannot be parsed to simplify troubleshooting.
- Strengthened the overall security posture of the Security Console by upgrading the bundled Axios library to the latest supported minor version.
- Improved the performance and responsiveness of the Asset Search API, particularly for larger Security Console deployments.
- Added built-in policy support for:
- DISA STIG Microsoft SQL Server Database 2022 Benchmark V1R3
- DISA STIG Microsoft SQL Server Instance 2022 Benchmark V1R4
- Operating System Support: Added support for Microsoft Windows Server 2025 on the Vulnerability Management (InsightVM) Console, Nexpose Console, and Scan Engines.
Fixed:
- Resolved an issue where the GET Scan Engine Sites API returned an incomplete value for scanTemplateName. The endpoint now returns the expected scan template name.
- Fixed an issue where CSV vulnerability reports did not include tabular solution content, such as Windows Registry settings and configuration values. This information is now exported correctly.
Digital Risk Protection (Threat Command)
Software release date: [June 19, 2026] | Release notes published: [July 6, 2026]
New:
- You can now control whether infostealer alerts include external user matches — credentials associated with a customer-owned domain but without an organizational email address. The toggle is located under Configurations > Customization in Digital Risk Protection (Threat Command), or under Intelligence > DRP Configurations > Customization in the Command Platform. External user alerting is on by default, preserving existing behavior. When turned off, monitoring stops for external email matches while internal organizational email monitoring continues. This setting applies to future alerts only and has no effect on existing or previously resolved alerts.
Rapid7 Agent (Insight Agent)
Version 4.1.1 (Unchanged from previous release version)
Fixed:
Resolved an issue in a third-party Go library that prevented some Rapid7 Agent (Insight Agent) capabilities from working as intended on devices with Apple M5 Pro and M5 Max chipsets. The following capabilities are now restored on affected devices:
- Endpoint Protection and Ransomware Prevention
- Agent-based Policy
- Hosted Velociraptor
- On-demand vulnerability scans
If Command Platform (Insight Platform)-managed agent updates are enabled, the Rapid7 Agent (Insight Agent) will automatically update the Endpoint Broker, Agent Core, and Hosted Velociraptor components. For more information, see Data collected by the Rapid7 Agent (Insight Agent) and Command Platform (Insight Platform)-managed agent updates .
Next-Generation Antivirus
No updates released at this time.
Ransomware Prevention
No updates released at this time.
Velociraptor
Version 0.74.4.27
Software release date: [July 8, 2026] | Release notes published: [July 8, 2026]
Fixed:
Resolved an issue in a third-party Go library that prevented the Rapid7 Velociraptor client from working as intended on devices with Apple M5 Pro and M5 Max chipsets. For more information, see the Rapid7 Agent Release Notes.
Automation (InsightConnect)
No updates released at this time.
Rapid7 Network Sensor (Insight Network Sensor)
Version 2.0.0.2
Software released: June 4, 2026 | Release notes published: July 14, 2026
Improved:
-
Removed DPDK as a dependency and replaced it with custom thread-management and memory allocations, resulting in a 7.6% packet capture performance improvement.
-
Raised thread limit from 16 to 32, resulting in better performance on 100 Gbps sensors with sufficient hardware.
-
This release includes improvements to event throughput.
Fixed:
- Fixed a bug where multicast flows would sometimes be assigned the wrong direction.
- Fixed protocol detection accuracy for STUN and mDNS.
New Protocols:
- WUDO: The sensor now detects the Windows Update Delivery Optimization (WUDO) protocol, which is used by Windows endpoints to share update content peer-to-peer across a local network.
- Cohesity RPC protocol: The sensor now detects the Cohesity Remote Procedure Call (RPC) protocol, used by the Cohesity Data Protection and Security Platform.
- Aerohive Mobility Routing protocol: The sensor now detects the Aerohive Mobility Routing protocol, used by Aerohive wireless infrastructure for access point coordination.